Skip to main content

Vendor/product archive

cybozu / office CVEs

Beta · best-effort

71 CVEs tagged to cybozu / office1 Critical, 4 High, 65 Medium, 1 Low, 0 Unrated.

CVE-2024-39817

Published Aug 6, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user do…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33311

Published Aug 18, 2022

Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Address Book via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33151

Published Aug 18, 2022

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32583

Published Aug 18, 2022

Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32544

Published Aug 18, 2022

Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Project via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32453

Published Aug 18, 2022

HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32283

Published Aug 18, 2022

Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Cabinet via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30693

Published Aug 18, 2022

Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the product via unspecified vecto…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30604

Published Aug 18, 2022

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29891

Published Aug 18, 2022

Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29487

Published Aug 18, 2022

Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28715

Published Aug 18, 2022

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25986

Published Aug 18, 2022

Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20634

Published Mar 18, 2021

Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20633

Published Mar 18, 2021

Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20632

Published Mar 18, 2021

Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bullet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20631

Published Mar 18, 2021

Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20630

Published Mar 18, 2021

Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20629

Published Mar 18, 2021

Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20628

Published Mar 18, 2021

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20627

Published Mar 18, 2021

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20626

Published Mar 18, 2021

Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20625

Published Mar 18, 2021

Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulle…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20624

Published Mar 18, 2021

Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Scheduler…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6023

Published Dec 26, 2019

Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 71 CVEsPage 1 of 3